Water Utility Cybersecurity for Western Washington
Control-network segmentation, 24/7 SCADA monitoring, and incident response readiness for water districts, PUDs, municipalities, and wastewater systems — from a team that has secured the systems delivering clean water since 2003.
Since late July 2026, water and wastewater utilities in at least seven states have reported cyber intrusions — the FBI and EPA confirmed that attackers reached internet-exposed control systems, changed device passwords and IP addresses, and in some communities forced manual operations and boil-water advisories. No Washington system has been publicly named, but the Washington State Department of Health has warned hundreds of drinking-water providers, and the state's cybersecurity planning covers only the 249 largest suppliers. For most of Western Washington's small and mid-sized water districts, there is no state program coming. Securing your system is on you.
Spyderweb Communications has worked with water utility systems since 2003 — SCADA front-ends, PLC control networks, telemetry, backflow assembly management software, and meter-reading platforms like Badger and Sensus — and our team's water experience runs back to the late 1990s. This is not a service line we added when water systems hit the news. It is where we started: designing control networks that are fully segregated from business networks and the public internet, so an attacker scanning for exposed equipment never finds yours.
Our approach matches what federal guidance now urges every utility to adopt. Layer-3 firewalls between layer-2 broadcast domains keep control traffic completely separated from office traffic. Control systems get zero direct internet exposure. Access into the control environment is brokered, logged, and tightly restricted. And our 24/7 managed security operations watch the SCADA front-end around the clock, because a Tuesday-at-2-a.m. password change on a pump controller should never go unnoticed until Wednesday morning.
Why Water Systems Are Under Attack Right Now
The July 2026 wave was not sophisticated, and that is the alarming part. Attackers found internet-facing PLCs — many with password protection never even enabled — locked operators out, and in some cases modified control logic. Officials widely believe the activity is linked to Iran, though no government has formally attributed it, and investigators are also weighing whether another state actor is imitating the 2023 CyberAv3ngers playbook. For a utility operator, attribution barely matters: the defense is identical either way.
The exposure is measurable. An EPA Office of Inspector General scan of 1,062 drinking water systems found 97 systems serving roughly 26.6 million people carrying critical or high-risk vulnerabilities. CISA's alert highlighted a subtler problem: undocumented cellular modems installed by operators, vendors, and integrators — connections that never appear on the network diagram and never get audited. Small systems were hit hardest, because small systems rarely have anyone whose job is to notice.
Water Utility Cyberattacks Hit at Least Seven States: What Western Washington Systems Should Do Now
What actually happened during the 2026 attack wave, why internet-exposed PLCs keep getting hit, and the specific steps — segmentation, monitoring, and removing shadow remote access — that Western Washington water systems should take now.
Read our analysis of the 2026 water utility attacks →What We Secure
Every connected system in a water utility, from the treatment plant to the meter at the curb — because the attack surface is never just SCADA.
How We Secure Water Systems
- Segmentation first. Layer-3 firewalls between layer-2 broadcast domains, so traffic between the office network, the SCADA front-end, and field controllers passes a checkpoint that permits only what the water system actually needs. No path from a billing PC or an email inbox to a pump controller. Zero direct internet exposure for any control device.
- Brokered, monitored access. When remote access is genuinely needed — and in a utility with staff on call, it usually is — it runs through a hardened gateway, every session logged and watched. No standing vendor tunnels, no forgotten cellular modems, no exceptions that outlive the service call that created them.
- Around-the-clock monitoring. SIEM-class monitoring on the control network's edge and endpoint protection on SCADA and HMI workstations, backed by our 24/7 managed security service. The 2026 intrusions announced themselves — password lockouts, controllers changing addresses, sites dropping offline. Monitoring is what turns those signals into a phone call instead of an outage.
- Know your exposure. A structured risk assessment maps every device, modem, and vendor connection into your control environment, and an external penetration test shows you exactly what an attacker sees from the outside. In our experience, the mapping always turns up at least one connection nobody remembered authorizing.
- Readiness for the bad day. The utilities that came through July 2026 best were the ones that could run manually and restore quickly. We build and rehearse that muscle with you — backup, recovery, and continuity planning scoped to how a water system actually operates.
Not sure whether your control system is exposed to the internet?
Ask us — the conversation is free. Call (253) 495-8000 or use the contact form.
Who We Serve Across Western Washington
We support water districts, PUDs, municipal water and wastewater systems, and the operators who keep them running — across Pierce, King, Thurston, and Kitsap counties and the whole Puget Sound region. From Tacoma and the state capital region, where regional wastewater infrastructure serves tens of thousands of connections, to 300-connection districts on well water, the systems out here match the size and profile of the utilities hit in July 2026 almost exactly.
If you operate a water system anywhere in Western Washington, you are in our service area. And if you are outside it, call anyway — we have yet to meet a water system we could not help, and utilities of every kind are part of the industries we serve.
Frequently Asked Questions
How are hackers attacking water utilities in 2026?
Through internet-exposed control equipment. The FBI and EPA's July 30, 2026 advisory describes attackers reaching internet-facing PLCs at utilities in at least seven states, changing device passwords and IP addresses so operators lost monitoring and control, and in at least one case modifying control logic. The common thread across every publicly reported incident is control hardware that was reachable from the public internet. Our analysis of the wave is in our full write-up of the 2026 water utility cyberattacks.
Are Washington water systems being targeted?
No Washington utility has been publicly named in the 2026 wave, but the Washington State Department of Health has warned hundreds of drinking-water providers about the campaign, and public water systems serve more than 6.2 million Washingtonians. The attacks exploited common vendor and integrator setups found nationwide — including here. The honest posture for any Western Washington system is to assume you are on the target list and verify your exposure.
Does Washington require cybersecurity for drinking water systems?
No. Washington does not currently regulate cybersecurity for drinking water systems, and the state's Cybersecurity Action Plan covers only the 249 largest suppliers plus roughly 100 wastewater systems. Most small water districts are responsible for their own defenses — which is exactly the gap attackers exploited in 2026. An independent risk assessment is the fastest way to find out where your system stands.
What should a small water district do after the July 2026 FBI/EPA alert?
Start with an inventory of every connection into your control system, including cellular modems and vendor telemetry links that may never have been documented. Then verify from the outside whether anything is reachable from the public internet, remove any direct exposure, put real segmentation between control and business networks, and add monitoring so the next intrusion attempt announces itself. The federal guidance is unambiguous: control systems should not answer the open internet.
What is OT network segmentation, and does my water system need it?
Segmentation means layer-3 firewalls standing between your layer-2 broadcast domains, so control traffic and business traffic never mix, and a control network that is fully segregated with zero direct internet exposure. If your SCADA front-end or PLCs share a network with office computers, email, or billing systems, you need it. It is the single discipline that would have prevented most of the publicly reported 2026 intrusions.
Do meter-reading and backflow systems need security attention too?
Yes. Meter-reading platforms like Badger and Sensus and backflow assembly management software were not implicated in any of the 2026 attacks — but they are connected systems that are routinely forgotten in security reviews, exactly the class of vendor-installed connectivity CISA warned about. Each one is a path into your network, and each one belongs in your inventory, your segmentation design, and your monitoring scope.
Ready to Secure
Your Business?
Get a free consultation with our Tacoma-based team. We've been securing Puget Sound businesses since 2003.
